Vulnerabilities > Resource Management Errors

DATE CVE VULNERABILITY TITLE RISK
2011-04-27 CVE-2011-1507 Resource Management Errors vulnerability in Digium Asterisk
Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections.
network
low complexity
digium CWE-399
5.0
2011-04-21 CVE-2011-1821 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search.
network
low complexity
ibm microsoft CWE-399
4.0
2011-04-21 CVE-2010-4789 Resource Management Errors vulnerability in IBM Tivoli Directory Server
Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (daemon crash) via a paged search that is interrupted by an LDAP Unbind operation.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2010-4787 Resource Management Errors vulnerability in IBM Tivoli Directory Server
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon hang) via a paged search that triggers improper mutex processing.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2010-4786 Resource Management Errors vulnerability in IBM Tivoli Directory Server
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon crash or hang) via a paged search, as demonstrated by a certain idsldapsearch command, related to an improper ibm-slapdIdleTimeOut configuration setting.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2010-4785 Resource Management Errors vulnerability in IBM Tivoli Directory Server
The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) on Linux, Solaris, and Windows allows remote authenticated users to cause a denial of service (ABEND) via a malformed LDAP extended operation that triggers certain comparisons involving the NULL operation OID.
network
low complexity
ibm linux microsoft sun CWE-399
4.0
2011-04-21 CVE-2009-5073 Resource Management Errors vulnerability in IBM Tivoli Directory Server
IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested group that contains the Distinguished Name (DN) of its parent entry.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2009-5072 Resource Management Errors vulnerability in IBM Tivoli Directory Server
Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memory consumption) via an empty string argument.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2008-7290 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allows remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2008-7288 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.
network
low complexity
ibm CWE-399
5.0